Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Metasploit Framework

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1078Valid AccountsEvidence1

The result is a certificate being issued with the privileges of that AD security group, and all groups it is a member of, even if the requester is not part of those groups.

Execution

1 technique
T1059.004Unix ShellEvidence1

MITRE ATT&CK Mapping Technique ID Evidence Command and Scripting Interpreter: Unix Shell T1059.004 Extensive bash usage for tool installation, payload generation

Persistence

1 technique
T1078Valid AccountsEvidence1

The result is a certificate being issued with the privileges of that AD security group, and all groups it is a member of, even if the requester is not part of those groups.

Privilege Escalation

3 techniques
T1055Process InjectionEvidence1

A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.

T1078Valid AccountsEvidence1

The result is a certificate being issued with the privileges of that AD security group, and all groups it is a member of, even if the requester is not part of those groups.

T1548Abuse Elevation Control MechanismEvidence1

By leveraging misconfigurations in ADCS implementations, threat actors are able to escalate their privileges and impersonate high-value domain accounts, up to and including domain admins, possibly leading to full domain compromise.

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence1

Generate a 32 bit raw shellcode in whatever framework you want... Run: cat payload.bin | base64 -w 0 ... Copy the base64 encoded payload into the code variable below

T1055Process InjectionEvidence1

A JavaScript and VBScript shellcode launcher. This will spawn a 32 bit version of the binary specified and inject shellcode into it.

T1078Valid AccountsEvidence1

The result is a certificate being issued with the privileges of that AD security group, and all groups it is a member of, even if the requester is not part of those groups.

Credential Access

2 techniques
T1606.001Web CookiesEvidence1

Through these techniques, threat actors abuse certificate templates which don’t require manager approval and include enrollment rights for low privileged users / groups.

T1649Steal or Forge Authentication CertificatesEvidence1

It can be used to detect misconfigurations, but also to issue certificates utilizing a large range of escalation techniques and leveraging them for domain authentication.

Command and Control

1 technique
T1071Application Layer ProtocolEvidence1

C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/C2 infrastructure.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.